Lucene search

K
osvGoogleOSV:GHSA-2MH8-GX2M-MR75
HistoryOct 17, 2019 - 6:15 p.m.

Out-of-Memory Error in Bouncy Castle Crypto

2019-10-1718:15:16
Google
osv.dev
26

0.006 Low

EPSS

Percentile

78.4%

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

CPENameOperatorVersion
org.bouncycastle:bcprov-jdk14eq1.63

References

0.006 Low

EPSS

Percentile

78.4%